Client Privacy Notice Template for the United Arab Emirates
Generate a bespoke document
What is a Client Privacy Notice?
The Client Privacy Notice is a mandatory document required under UAE Federal Decree-Law No. 45/2021 on Personal Data Protection, designed to inform clients about how their personal data is collected, used, and protected. This document serves as a transparent communication tool between organizations and their clients, detailing the types of personal information collected, the purposes for processing, data sharing practices, and the rights of individuals regarding their personal data. The notice must be tailored to comply with UAE federal regulations, as well as specific requirements that may apply in free zones such as the DIFC and ADGM. Organizations should implement this document before collecting any personal data and must ensure it remains current with evolving data protection laws and organizational practices.
About the Client Privacy Notice
A Client Privacy Notice is your organization's formal commitment to transparency in data handling practices under United Arab Emirates law. This mandatory document ensures you comply with Federal Decree-Law No. 45/2021 while building trust with clients by clearly explaining how you collect, use, and protect their personal information.
When do you need this document?
You must provide a Client Privacy Notice before collecting any personal data from clients, customers, or service users. This requirement applies whether you operate a healthcare facility collecting patient information, a financial services firm processing client portfolios, an e-commerce platform gathering customer details, or any business that handles personal data. The notice is particularly critical when launching new services, updating data collection practices, or expanding operations into new jurisdictions within the UAE. Organizations in specialized zones like DIFC and ADGM face additional compliance obligations that must be addressed in their privacy notices.
Key legal considerations
Your privacy notice must clearly identify the legal basis for processing personal data under UAE law, whether for contract performance, legal compliance, legitimate interests, or consent. You must specify data retention periods, outline security measures, and explain clients' rights including access, correction, deletion, and data portability. The document should detail any international data transfers and the safeguards in place, particularly important given UAE restrictions on cross-border data flows. You must also designate clear contact information for privacy inquiries and complaints, including details of your Data Protection Officer where required. Regular updates to the notice are mandatory when processing activities change or new legal requirements emerge.
Legal requirements in United Arab Emirates
Under Federal Decree-Law No. 45/2021, your privacy notice must be provided in Arabic and English, clearly written, and easily accessible to data subjects. The UAE Data Protection Office requires specific disclosures about data categories, processing purposes, and third-party sharing arrangements. Organizations in the Dubai International Financial Centre must additionally comply with DIFC Law No. 5 of 2020, which incorporates GDPR-style requirements for privacy notices. ADGM entities must follow the ADGM Data Protection Regulations 2021, which similarly mandate comprehensive privacy disclosures. Healthcare organizations face additional obligations under Federal Law No. 2 of 2019 regarding health data privacy. The notice must be provided at the point of data collection and be readily available on your website or premises, with any material changes communicated to affected individuals within the timeframes specified by applicable law.
GOVERNING LAW
Applicable law
This Client Privacy Notice is drafted to comply with United Arab Emirates law. Key legislation includes:
DIFC Law No. 5 of 2020: Data Protection Law specific to the Dubai International Financial Centre, which aligns with GDPR standards and applies to companies operating within the DIFC
ADGM Data Protection Regulations 2021: Abu Dhabi Global Market's data protection regulations, governing the processing of personal data by ADGM entities
Federal Law No. 2 of 2019: Concerning the Use of Information and Communication Technology in Healthcare, containing provisions for protecting health data privacy
Federal Decree-Law No. 34 of 2021: Concerning Combating Rumors and Cybercrimes, including provisions related to privacy violations and unauthorized access to personal data
Federal Law No. 15 of 2020: Consumer Protection Law, which includes provisions related to protecting consumer data and privacy rights
UAE Constitution: Articles 31 and 32 establish the fundamental right to privacy and confidentiality of communications
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it